Security
Designed for enterprise data environments.
Isolation is a database property, not a filter in application code. Authentication is delegated to an identity provider. Secrets never sit in the projection. That is the whole of the claim.
-
Tenant isolation
Every projection table has row-level security enabled and forced. The API refuses to start if the database role can bypass it.
-
OIDC sign-in
The application authenticates with an identity provider over OpenID Connect. Roles are checked on every request.
-
Role-based access
Viewer, modeler, steward, release manager and admin are separate permissions. An admin is not automatically a modeler.
-
Secrets by reference
Git tokens and connection passwords are stored as the name of a secret, never the value. The product rejects a pasted token.
-
Audit events
Tenant-scoped actions are written to an append-only event log: who did what, to which object, and when.
-
Customer-owned Git
The model of record lives in your repository. The hosted service holds a rebuildable projection, not the source of truth.
Not claimed yet
- SAML and SCIM directory sync
- Enforced SSO for a verified domain
- SOC 2 and similar certifications — not claimed until they exist
Security practices evolve with the product. Contact [email protected] for security questions, or to report a vulnerability.
The platform is invite-only. Sign in if you already have an account. Otherwise request a demo.